Skip to content

SOC – Latest CVEs

Live vulnerability feed from NVD

Feed timestamp 2026-07-24 20:14:31 UTC
CRITICAL
HIGH
MEDIUM
LOW

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa…

Published: 2026-03-31 Modified: 2026-07-24

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau…

Published: 2026-03-31 Modified: 2026-07-24

RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form…

Published: 2026-03-31 Modified: 2026-07-24

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t…

Published: 2026-03-31 Modified: 2026-07-24

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to c…

Published: 2026-03-31 Modified: 2026-07-24

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. …

Published: 2026-03-31 Modified: 2026-07-24

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that…

Published: 2026-03-31 Modified: 2026-07-24

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where…

Published: 2026-03-31 Modified: 2026-07-24

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to …

Published: 2026-03-31 Modified: 2026-07-24

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th…

Published: 2026-03-31 Modified: 2026-07-24